All payments made in the preview are in test mode. Read more

Trust Center

Security at GuardSource

You are trusting us with officer locations, incident reports and client records. Here is exactly how we protect them. Last reviewed September 9, 2026.

Compliance

Where we stand today

SOC 2 Type II

In progress

Controls are implemented and evidence collection is running. The observation window is underway; the report will be available under NDA once the audit completes.

ISO/IEC 27001:2022

In progress

An Information Security Management System is documented and operating against the 93 Annex A controls. Stage 1 and Stage 2 certification audits with an accredited body are the remaining steps.

GDPR / UK GDPR

Aligned

Data processing addendum, Standard Contractual Clauses, published sub-processor list, documented retention schedule and a 30-day data subject request process.

CCPA / CPRA

Aligned

Notice at collection, request handling and non-discrimination. We do not sell or share personal data.

Penetration testing

Planned

An independent external test is scheduled ahead of general availability; the summary letter will be shareable under NDA.

Controls

How the platform is built

These are the controls in place today, not aspirations. Each one is evidenced in our SOC 2 readiness programme and mapped to ISO/IEC 27001:2022 Annex A.

Encryption

TLS 1.2 or better for everything in transit. AES-256 for data at rest, including database volumes, file storage and backups.

Access control

Least-privilege, role-based access to production. Single sign-on with mandatory multi-factor authentication for staff. Access is reviewed quarterly and revoked the day someone leaves.

Tenant isolation

Row-level security enforced at the database, so a query can only ever return the rows belonging to the authenticated account.

Audit logging

Append-only logs of authentication, plan changes, data exports and deletion requests. Logs cannot be edited or deleted by any application role and are retained for two years.

Backups and recovery

Automated encrypted daily backups with point-in-time recovery. Restores are tested on a regular schedule. Recovery targets: RPO 24 hours, RTO 8 hours.

Monitoring

Continuous uptime and error monitoring with on-call alerting, plus dependency vulnerability scanning on every build.

Secure development

Peer-reviewed changes, automated type and lint checks, separate development and production environments, and secrets held in a managed secret store — never in source code.

Incident response

A documented response plan with defined severities and owners. Confirmed personal data breaches are reported to affected customers within 48 hours of confirmation.

Vendor management

Every sub-processor is reviewed for security and privacy posture before onboarding and re-reviewed annually. The current list is published.

Reporting

Responsible disclosure

If you believe you have found a vulnerability, email security@guardresourceone.com with enough detail to reproduce it. We acknowledge reports within two business days and aim to confirm a fix timeline within ten.

Please do not run automated scans against production, access data that is not yours, or disclose the issue publicly before we have had a chance to fix it. We will not pursue legal action against researchers who follow these guidelines.

Requesting documents? Our Data Processing Addendum, sub-processor list and Privacy Policy are public, as is our ISO/IEC 27001 control mapping. The SOC 2 report and penetration test summary are shared under NDA once available.